Claude Code skills · updated 2026-10-03
Firmware release security skill for Claude Code — secure boot, OTA, debug
Find the sdkconfig and prj.conf lines that must not ship in production firmware
On the bundled sdkconfig.defaults: 9 findings (6 errors, 2 warnings, 1 info) in 1 file from 18 rules, including secure boot off and OTA over plain HTTP.
Get it on Whop - $12 onceGet it on Gumroad
Who it's for
For ESP32 and Zephyr firmware engineers cutting a production image from a config that started on the bring-up branch.
What breaks, and when
Ship it and every unit boots any image written to flash, accepts OTA over plain HTTP and keeps JTAG reachable, and the release build is the moment it gets locked in.
What it printed on the bundled example
== Firmware Release Gate for sdkconfig and prj.conf — 9 findings (6 errors, 2 warnings, 1 info) in 1 file · 18 rules
ERROR sdkconfig.defaults:8 [secure_boot_off]
Secure boot is off: the ROM will boot any image written to flash. Set CONFIG_SECURE_BOOT=y and choose the Secure Boot V2 scheme before the release build.
ERROR sdkconfig.defaults:10 [flash_enc_dev_mode]
Flash encryption is in Development mode: the unit still accepts re-flashing and the key stays readable. Production units need CONFIG_SECURE_FLASH_ENCRYPTION_MODE_RELEASE=y.
ERROR sdkconfig.defaults:11 [secure_boot_allow]
A secure-boot escape hatch is enabled, so JTAG, the ROM console or the UART bootloader stays reachable on a locked unit. Remove every CONFIG_SECURE_BOOT_ALLOW_* line from the release config.
WARN sdkconfig.defaults:12 [nvs_encryption_off]
NVS encryption is off: Wi-Fi credentials and tokens sit in cleartext in the NVS partition. Set CONFIG_NVS_ENCRYPTION=y.
What you get
- SKILL.md, an offline Node scanner and the 18-rule table
- file:line, severity and the CONFIG_ setting to use instead
- Line edits for sdkconfig and prj.conf, applied only after you agree
- CI: node scripts/scan.js . exits 1 on any error
Install
Unzip into ~/.claude/skills/ (all projects) or your-repo/.claude/skills/ (one repo), then ask Claude Code: "We're cutting the production firmware build for our ESP32 gateway this week. Is the sdkconfig in this repo safe to ship to customers? Don't edit anything yet.". Needs Node 16+.
unzip firmware-release-security-check.zip -d ~/.claude/skills/
Ask Claude
“We're cutting the production firmware build for our ESP32 gateway this week. Is the sdkconfig in this repo safe to ship to customers? Don't edit anything yet.”
What it does not do
It does not build the image, run menuconfig or touch eFuses; it reads config text only. No network calls, no edits without your OK.
FAQ
What is a Claude Code skill?
A folder with a SKILL.md and scripts that Claude Code loads when your request matches it. You ask in plain words and Claude runs the scanner the skill carries.
How is this different from asking Claude without the skill?
The skill carries a dated rule table and a scanner that reads every file, so Claude quotes the exact date and line instead of answering from memory.
Does it send my code anywhere?
It does not build the image, run menuconfig or touch eFuses; it reads config text only. No network calls, no edits without your OK.
How do I install it?
Unzip into ~/.claude/skills/ (all projects) or your-repo/.claude/skills/ (one repo), then ask Claude Code: "We're cutting the production firmware build for our ESP32 gateway this week. Is the sdkconfig in this repo safe to ship to customers? Don't edit anything yet.". Needs Node 16+.
What do I get when I buy?
The zip. On Whop it is in your library as a download lesson with the zip attached; on Gumroad it is the product file.